Data Protection & GDPR
Practical, risk-focused data protection advice for Greece and cross-border operations, helping businesses navigate evolving regulatory and technology challenges.
We advise businesses and organisations on all aspects of Greek and EU data protection law, including compliance with the General Data Protection Regulation (GDPR) and applicable Greek legislation. Our practice covers the design and implementation of data protection compliance programmes, drafting and review of privacy policies and notices, data processing agreements, international data transfers, data subject rights, data breaches and regulatory investigations. We support clients in establishing governance frameworks that ensure ongoing compliance and accountability across their operations.
We assist clients with data protection issues arising in employment, commercial, corporate and technology matters, including workplace privacy, due diligence, outsourcing and vendor arrangements. Our team advises on the allocation of responsibilities between controllers and processors, data protection impact assessments (DPIAs), records of processing activities (RoPAs) and interactions with the Hellenic Data Protection Authority. We also guide clients through complex questions relating to cloud services, digital platforms, AI‑driven processing, cybersecurity requirements and sector‑specific regulatory obligations.
Our approach combines practical, risk‑based advice with a clear understanding of the regulatory requirements applicable to businesses operating in Greece and across multiple jurisdictions. We work closely with clients to develop solutions that are legally sound, operationally feasible and aligned with their commercial objectives, supporting them in managing data protection risks in a rapidly evolving regulatory and technological environment.